diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index fd3bb39..c84ce37 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -1375,7 +1375,11 @@ test("a service is reached by a name under the machine it runs on", { // // The mesh writes the data; a module runs the daemon. Both manifests are read from the // repository rather than written here, so what is proven is what ships. - for (const name of ["dnsmasq", "resolv-conf"]) { + // `resolved-split-dns`, not `resolv-conf`: these machines run systemd-resolved, which owns + // /etc/resolv.conf. The two claim the same thing precisely so that assigning the wrong one is a + // refusal rather than a fight over the file — and picking the wrong one here would have been + // testing that fight. + for (const name of ["dnsmasq", "resolved-split-dns"]) { const manifest = readFileSync(`${moduleExamples}/${name}.json`, "utf8"); await must("anchor", `cat > /tmp/${name}.json <<'MANIFEST'\n${manifest}\nMANIFEST`); await must("anchor", `docker cp /tmp/${name}.json mesh-control:/${name}.json`); @@ -1387,7 +1391,7 @@ test("a service is reached by a name under the machine it runs on", { // does, which is the arrangement this design refuses everywhere else. for (const machine of ["anchor", "laptop"]) { await mesh(`assign ${machine} dnsmasq`); - await mesh(`assign ${machine} resolv-conf`); + await mesh(`assign ${machine} resolved-split-dns`); } await mesh("push"); await new Promise((r) => setTimeout(r, 25_000)); @@ -1454,7 +1458,7 @@ test("a service is reached by a name under the machine it runs on", { "the resolver answered for a name that is not the mesh's"); for (const machine of ["anchor", "laptop"]) { - await mesh(`unassign ${machine} resolv-conf`); + await mesh(`unassign ${machine} resolved-split-dns`); await mesh(`unassign ${machine} dnsmasq`); } await mesh("push");